Backdoor

Backdoor:Win32/Dridex.SD!MTB information

Malware Removal

The Backdoor:Win32/Dridex.SD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Dridex.SD!MTB virus can do?

  • At least one process apparently crashed during execution
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Mimics the file times of a Windows system file
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Appends a known Locked ransomware file extension to files that have been encrypted
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Dridex.SD!MTB?


File Info:

crc32: EA4A439D
md5: 3ef112d6b8935cf7f453471a37a93acc
name: 3EF112D6B8935CF7F453471A37A93ACC.mlw
sha1: 268e82c79135efa0f83c08ab4fff96ddc81cba98
sha256: 2818f4e55c9237a7f48a93ab2c9faf02cc5f4adfa4a3c5b08226a2752b083e54
sha512: 94babf5b82eb088dbf3c31fba0ee995dbb5491ed0688b877eeb41f561b5c0879c7eee7ff76ca29a8b8aaab31940795a423758a9f2a71c70292743ae40799323e
ssdeep: 1536:tbh3/JJ71XJVqwQvpOGEbAeKjB/Q/JgW771:tlJ/XJVqwQqm/Q/Jf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Dridex.SD!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.BitPaymer.D
FireEyeGeneric.mg.3ef112d6b8935cf7
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXGD-QF!3EF112D6B893
CylanceUnsafe
AegisLabTrojan.Win32.Cryptor.j!c
SangforRansom.Win32.Cryptor.bum
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Ransom.BitPaymer.D
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.6b8935
BitDefenderThetaGen:NN.ZexaF.34590.eqX@a0Eyd3c
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.FriedEx.D
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.DoppelPaymer-7441266-0
KasperskyTrojan-Ransom.Win32.Cryptor.bum
NANO-AntivirusTrojan.Win32.Encoder.fltiqt
RisingRansom.Cryptor!8.10A9 (CLOUD)
Ad-AwareTrojan.Ransom.BitPaymer.D
SophosMal/Generic-R + Mal/FriedEx-A
ComodoMalware@#3lzgv1kptpooj
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Encoder.25571
ZillyaTrojan.Filecoder.Win32.9949
McAfee-GW-EditionGenericRXGD-QF!3EF112D6B893
EmsisoftTrojan.Ransom.BitPaymer.D (B)
IkarusTrojan-Ransom.Friedex
JiangminTrojan.Cryptor.lk
AviraTR/Dropper.Gen
MAXmalware (ai score=97)
Antiy-AVLTrojan/Win32.Streamer
MicrosoftBackdoor:Win32/Dridex.SD!MTB
ArcabitTrojan.Ransom.BitPaymer.D
ZoneAlarmTrojan-Ransom.Win32.Cryptor.bum
GDataTrojan.Ransom.BitPaymer.D
CynetMalicious (score: 100)
VBA32TrojanRansom.Cryptor
ALYacTrojan.Ransom.BitPaymer.D
TACHYONRansom/W32.Cryptor.73728
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/CI.A
TencentWin32.Trojan.Raas.Auto
YandexTrojan.GenAsa!kQ8ad+hOOT0
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.CKGJ!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Ransom.4ee

How to remove Backdoor:Win32/Dridex.SD!MTB?

Backdoor:Win32/Dridex.SD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment